LiteLLM gateways default admin key exposure security flaw
Vulnerability
Summary
Hide ▲
Show ▼
LiteLLM gateways that still accept the default sk-1234 admin key expose administrator access paths, allowing access to stored provider API keys and, in tests, cloud IAM credentials. Wiz Research found the issue on 294 of 3,074 internet-facing instances it scanned in February. The default credential turns an exposed gateway into a high-value secrets store risk. Operators can reduce exposure by replacing the key with a long random value.
Related Happenings
AWS access keys publicly exposed and still valid
Data Leak
H score33
First: 21.08.2026 18:55
Last: 21.08.2026 18:55
Sources 1
About this happening:
More than 9,300 AWS access keys exposed in public sources between August 2022 and August 2026 remained active and valid, creating a live risk of cloud account takeover...
AWS access keys publicly exposed and still valid
Data LeakAbout this happening: More than 9,300 AWS access keys exposed in public sources between August 2022 and August 2026 remained active and valid, creating a live risk of cloud account takeover...
Daxin and Stupig active on a Taiwan manufacturing host in 2026
Malware Activity
H score27
First: 16.07.2026 14:17
Last: 16.07.2026 14:17
Sources 1
About this happening:
The Daxin rootkit resurfaced on a compromised host in Taiwan in 2026, showing that the malware still maintains stealthy access inside a manufacturing network. The same...
Daxin and Stupig active on a Taiwan manufacturing host in 2026
Malware ActivityAbout this happening: The Daxin rootkit resurfaced on a compromised host in Taiwan in 2026, showing that the malware still maintains stealthy access inside a manufacturing network. The same...
TaskWeaver and Djinn Stealer delivered through abused SimpleHelp RMM tools
Malware Activity
H score36
First: 30.06.2026 18:34
Last: 30.06.2026 18:34
Sources 1
About this happening:
The abuse of SimpleHelp RMM turned a trusted support channel into a malware delivery path for TaskWeaver and Djinn Stealer, expanding attacker reach into managed netwo...
TaskWeaver and Djinn Stealer delivered through abused SimpleHelp RMM tools
Malware ActivityAbout this happening: The abuse of SimpleHelp RMM turned a trusted support channel into a malware delivery path for TaskWeaver and Djinn Stealer, expanding attacker reach into managed netwo...
Trivy environment credentials leak
Data Leak
H score37
First: 21.03.2026 19:30
Last: 21.03.2026 19:30
Sources 1
About this happening:
The Trivy environment credentials leak exposed stolen authentication secrets and helped enable a later compromise, raising the risk of follow-on abuse. The credentials came fr...
Trivy environment credentials leak
Data LeakAbout this happening: The Trivy environment credentials leak exposed stolen authentication secrets and helped enable a later compromise, raising the risk of follow-on abuse. The credentials came fr...
Bitwarden adds passkey login for Windows 11 sign-in
Security Tool/Service
H score11
First: 05.03.2026 00:34
Last: 05.03.2026 00:34
Sources 1
About this happening:
Bitwarden added passkey login for Windows 11, expanding passwordless sign-in and reducing phishing exposure for users who store credentials in the vault.
Bitwarden adds passkey login for Windows 11 sign-in
Security Tool/ServiceAbout this happening: Bitwarden added passkey login for Windows 11, expanding passwordless sign-in and reducing phishing exposure for users who store credentials in the vault.
Timeline
-
10.09.2026 10:12 2 articles · 3h ago
LiteLLM gateways default admin key exposure security flaw
Initial DisclosureIn February, Wiz Research found that a substantial share of internet-facing LiteLLM gateways still accepted the default sk-1234 admin key. That left exposed deployments with administrator access to stored secrets and, in tests, cloud credentials.
Show sources
- Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key — thehackernews.com — 10.09.2026 10:12
- Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key — thehackernews.com — 10.09.2026 10:12